Creating an Advanced ECA search

Last published : Jun 29, 2026
You can create an advanced ECA search in the following ways:
To create an Advanced ECA search:
  1. On the Investigations tab, select Managed Accounts>New Search.
  2. Perform advanced search or query search to get the expected items. See Performing Advanced Search and Query Search.
  3. Click Save Search.
  4. In the Save Search dialog box, enter a unique name for the search.
  5. Select the Advanced ECA check box.
    Note: After you select the Advanced ECA check box, the application disables the Tag name field, the On-going check box, and the Legal Hold check box.
  6. To send this search to a particular case, select the Send to Case check box, and select a valid case from the drop-down list.
    Note: The Keep copy in Investigations remains selected by default. When you send the Advanced ECA search from the Investigations tab to a Case in the eDiscovery tab, it gets saved under Research Sets. After sending this Advanced ECA search to Case, it may show different result (email count) depending on the custodians selected in the Case Setup option. For AI-enabled cases,Send to Case supports only email items, and any non-email items (such as files and collaboration messages) are automatically skipped.
  7. Click Save.
    The search appears under the Advanced ECA node in the left navigation pane.
    After the search is created, you can select the appropriate filter options to refine the search results. For example, under Filters, expand FormatType and select MS Teams to view only MS teams related search results.
    In a single Advanced ECA search, the application can save maximum 1000000 records each for emails, collaboration messages, and files.
    Note: If the Advanced ECA search processing fails, you need to click Please try again to retry processing. If this search fails consecutively, you need to delete the search and create a new search again.